CVE-2024-25605: Medium severity Liferay Digital Experience Platform vulnerability
The Journal module in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions grants guest users view permission to web content templates by default, which allows remote attackers to view any template via the UI or API.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/com.liferay.portal:release.dxp.bomto a version that resolves this vulnerability.Fixed in 7.2.10.fp17 - Upgrade
Upgrade
maven/com.liferay.portal:release.portal.bomto a version that resolves this vulnerability.Fixed in 7.4.3.5-ga5 - Upgrade
Upgrade
Liferay Portal/Journals (Journal module)to a version that resolves this vulnerability.Fixed in 7.4.13 - Upgrade
Upgrade
Liferay Portal/Journals (Journal module)to a version that resolves this vulnerability.Fixed in 7.3Patch service pack 3 - Upgrade
Upgrade
Liferay Portal/Journals (Journal module)to a version that resolves this vulnerability.Fixed in 7.2Patch fix pack 17
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25605?
CVE-2024-25605 has a critical severity level due to the potential unauthorized access to web content templates by guest users.
How do I fix CVE-2024-25605?
To fix CVE-2024-25605, upgrade Liferay Portal to version 7.4.3.5 or later, or apply the relevant patches to earlier affected versions.
What versions are affected by CVE-2024-25605?
CVE-2024-25605 affects Liferay Portal versions 7.2.0 through 7.4.3.4, and older unsupported versions as well.
What types of attacks are possible due to CVE-2024-25605?
CVE-2024-25605 could allow remote attackers to view sensitive web content templates without proper authorization.
Who is at risk due to CVE-2024-25605?
Any Liferay Portal or Liferay DXP user operating on affected versions is at risk due to the improper granting of view permissions to guest users.